2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-35394CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as...
CVE-2021-35393CRITICAL9.8Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP...
CVE-2021-24527CRITICAL9.8The User Registration & User Profile – Profile Builder WordPress plugin before 3.4.9 has a bug allowing any user to rese...
CVE-2021-25955CRITICAL9In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows l...
CVE-2021-37705CRITICAL10OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl...
CVE-2021-21830CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ X...
CVE-2021-21829CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem funct...
CVE-2021-38302CRITICAL9.8The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
CVE-2021-36789CRITICAL9.8The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
CVE-2021-34823CRITICAL9.1The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in...
CVE-2021-3352CRITICAL9.1The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0...
CVE-2021-36380CRITICAL9.8Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns...
CVE-2021-32071CRITICAL9.8The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due t...
CVE-2021-1104CRITICAL9.8The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) regis...
CVE-2021-38621CRITICAL9.1The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30...
CVE-2021-27741CRITICAL9.1" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
CVE-2021-37353CRITICAL9.8Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
CVE-2021-37350CRITICAL9.8Nagios XI before version 5.8.5 is vulnerable to SQL injection vulnerability in Bulk Modifications Tool due to improper i...
CVE-2021-37346CRITICAL9.8Nagios XI WatchGuard Wizard before version 1.4.8 is vulnerable to remote code execution through Improper neutralisation ...
CVE-2021-37344CRITICAL9.8Nagios XI Switch Wizard before version 2.5.7 is vulnerable to remote code execution through improper neutralisation of s...
CVE-2021-31698CRITICAL9.8Quectel EG25-G devices through 202006130814 allow executing arbitrary code remotely by using an AT command to place shel...
CVE-2021-31556CRITICAL9.8An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not e...
CVE-2021-29377CRITICAL9.8Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary cod...
CVE-2021-28890CRITICAL9.8J2eeFAST 2.2.1 allows remote attackers to perform SQL injection via the (1) compId parameter to fast/sys/user/list, (2) ...
CVE-2021-28121CRITICAL9.8Virtual Robots.txt before 1.10 does not block HTML tags in the robots.txt field.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now